首页> 外文会议>IEEE international conference on computer science and information technology;ICCSIT 2010 >A Real-Time DDoS Attack Detection and Prevention System Based on per-IP Traffic Behavioral Analysis
【24h】

A Real-Time DDoS Attack Detection and Prevention System Based on per-IP Traffic Behavioral Analysis

机译:基于每IP流量行为分析的实时DDoS攻击检测与防御系统

获取原文

摘要

While many offline-based detection approaches have been well studied, the on-line detection of DOoS attack at leaf router near victims still poses quite a challenge to network administrators. Based on per-IP traffic behavioral analysis, this paper presents a real-time DDoS attack detection and prevention system which can be deployed at the leaf router to monitor and detect DDoS attacks. The advantages of this system lie in its statelessness and low computation overhead, which makes the system itself immune to flooding attacks. Based on the synchronization of TCP and LDP protocol behavior, this system periodically samples every single IP user's sending and receiving traffic and judges whether its traffic behavior meets the synchronization or not. A new non-parametric CUSUM algorithm is applied to detect SYN flooding attacks. Moreover, this system can recognize attackers, victims and normal users, and filter or forward IP packets by means of a quick identification technique. Finally, experiment results show that the system can make a real-time detection for flooding attacks at the early attacking stage, and take effective measures to quench it
机译:尽管已经对许多基于脱机的检测方法进行了很好的研究,但是在受害者附近的分支路由器上在线检测DOoS攻击仍然给网络管理员带来了很大的挑战。基于每IP流量行为分析,提出了一种实时DDoS攻击检测与防御系统,可以将其部署在叶子路由器上,以监视和检测DDoS攻击。该系统的优势在于它的无状态性和较低的计算开销,这使得系统本身可以免受洪泛攻击。该系统基于TCP和LDP协议行为的同步,定期采样每个IP用户的发送和接收流量,并判断其流量行为是否满足同步要求。一种新的非参数CUSUM算法被应用于检测SYN泛洪攻击。此外,该系统可以识别攻击者,受害者和普通用户,并通过快速识别技术过滤或转发IP数据包。最后,实验结果表明,该系统可以在攻击初期对洪水攻击进行实时检测,并采取有效措施对其进行淬灭。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号